[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fn4jZ2553BHf7LpUdbHQH48RkgjhntAm2JH0lWhW_V7Y":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"fb1c1e9a-70dc-4264-afab-a04b8860717f","ransomware-disrupts-colombian-ministry-of-justice-during-presidential-transition","60e52332-a2f4-4f71-81ba-f5dc24d7f49f","Ransomware Disrupts Colombian Ministry of Justice During Presidential Transition","The Colombian Ministry of Justice fell victim to a ransomware attack at a critically sensitive political moment, exposing systemic weaknesses in government cybersecurity preparedness. Ransomware actors frequently target government entities during periods of transition or distraction, knowing that response capacity may be reduced and pressure to restore operations is high. The attack highlights that critical public-sector infrastructure often lacks mature incident response plans, tested backups, and adequate network segmentation to contain lateral movement. This matters because disruption to justice systems can have cascading effects on civil rights, legal proceedings, and public trust in government institutions.","**Immediate actions:**\n- Activate and test existing incident response plans specifically for ransomware scenarios before high-risk periods such as government transitions.\n- Isolate affected systems immediately and disconnect them from the broader network to prevent lateral spread.\n\n**Long-term improvements:**\n- Implement immutable, air-gapped backups for all critical government systems and test restoration procedures at least quarterly.\n- Enforce strict network segmentation between public-facing services and sensitive internal justice system databases.\n- Establish a dedicated government Computer Security Incident Response Team (CSIRT) with clear escalation paths and authority.\n\n**Detection measures:**\n- Deploy endpoint detection and response (EDR) tools across all ministry endpoints to identify ransomware behavior early.\n- Implement centralized SIEM logging to detect anomalous file encryption activity, large-scale data movement, or unusual privilege escalation in real time.",[12,13,14,15,16,17,18,19,20],"CIS Control 11 – Data Recovery","CIS Control 12 – Network Infrastructure Management","CIS Control 17 – Incident Response Management","NIST SP 800-61 – Computer Security Incident Handling Guide","NIST CP-9 – Information System Backup","NIST SC-7 – Boundary Protection","NIST IR-4 – Incident Handling","ISO\u002FIEC 27035 – Information Security Incident Management","ITIL – Service Continuity Management","published","2026-08-12T18:20:55.089949+00:00","2026-08-12T18:20:54.954+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fwww.darkreading.com\u002Fcyberattacks-data-breaches\u002Fransomware-hits-colombian-justice-ministry-presidential-transition","ransomware-hits-colombian-justice-ministry-days-before-presidential-transition-724af1","Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"182e11d5-57c4-444e-8ec8-4682ad60261b","Incident Response","incident-response","Slow detection, poor containment, missing playbooks","#14b8a6",{"id":36,"name":37,"slug":38,"description":39,"color":40},"c8ff5d73-dec9-4911-88ee-ed016a89f3f4","Backup & Recovery","backup-recovery","No backups, untested recovery, ransomware impact","#f43f5e",{"id":42,"name":43,"slug":44,"description":45,"color":46},"f43a7f30-5046-4b10-9dba-1a704139821e","Network Segmentation","network-segmentation","Lateral movement, flat networks, missing firewalls","#06b6d4",[]]